Phishing Campaign Exploits Google Storage to Deploy Remcos RAT

Phishing Campaign Exploits Google Storage to Deploy Remcos RAT

First seen 9 Apr 2026, 10:31 UTC RedditCybersecuritynewsGbhackers 83% similarity 67.5

Article Content

Browse articles
ThreatCluster

A phishing campaign has been detected that exploits Google Cloud Storage to deliver the Remcos remote access trojan (RAT). Attackers host a fake Google Drive login page on the legitimate domain storage.googleapis.com, which appears trustworthy to users and security tools. The phishing page collects user credentials, including email, password, and one-time passcode. Upon successful login, victims are prompted to download a malicious JavaScript file that initiates a multi-stage attack chain. This chain includes executing VBS scripts and using a legitimate Microsoft binary, RegSvcs.exe, to inject the Remcos payload into memory, making detection challenging. The use of trusted infrastructure allows the phishing links to bypass many security filters. Security professionals are advised to enhance monitoring for suspicious script activity and unusual file paths. The campaign is ongoing, affecting users globally.

Key Points: • Phishing campaign uses Google Cloud Storage to deliver Remcos RAT. • Attackers exploit trusted infrastructure to evade detection. • Multi-stage attack includes credential theft and malware injection.

ThreatCluster AI

Timeline

2026-04-08
Phishing campaign identified using Google Storage.
2026-04-09
Articles published detailing the attack method and impact.

Community

Browse all →